Who I am

Operationally credible. Strategically fluent.

The full record — how I work, where I've delivered, and what backs it up.

About

I build and lead information security programmes that organisations can actually rely on. With 8+ years across security operations, detection engineering, GRC, and incident response, I deliver outcomes, not policies that sit in a drawer.

I've averted an active ransomware attack and recovered 20+ compromised systems for a client. I've reduced pre-production vulnerabilities by 40%. I've led ISO 27001-aligned security audits for 10 enterprise clients across regulated industries. And at TryHackMe, the world's largest cybersecurity platform (trusted by 7M+ users), I designed certifications now used by hiring managers worldwide to verify real security readiness.

That combination of operational credibility and governance expertise is what makes a security programme work in practice, not just on paper. I can run a threat hunt, deploy a SIEM from scratch, and write a board-level risk report.

Experience

Where I've delivered.

Eight years, three organisations, one throughline: security that holds up under audit and under attack.

  1. Cyber Security Engineer & Researcher — Security Content & Certifications

    Jan 2022 – Mar 2026

    TryHackMe, Ltd · Remote (London, UK)

    Designed hands-on cybersecurity training and certification content — rooms, modules, and exams — on the world's largest security platform, trusted by 7M+ users globally.

    Certification contributions

    • SAL1 — Security Analyst Level 1: Contributed to TryHackMe's first professional certification from the ground up — scenario-based questions grounded in real SOC operations, hands-on alert-triage and incident-handling simulations, and improvements to the SOC Simulator. The exam covers 150+ questions across governance, risk, incident response, and defensive security.
    • SAL2 — Security Analyst Level 2: Designed advanced practical scenarios for phishing-analysis investigation and EDR triage, requiring candidates to apply real detection-and-response workflows under exam conditions.
    • SEC1 — Cyber Security 101: Developed the Security Operations challenge set — log analysis, threat detection, incident response, and SOC monitoring tools — for a foundational, career-entry certification.
    • SEC0 — Pre-Security: Contributed Attack & Defence strategy content, scenarios, and exam questions for the platform's beginner-entry certification.

    Rooms & content

    • Built and maintained a security content library across detection engineering, DFIR, cyber threat intelligence, SOAR, and EDR triage — using MITRE ATT&CK, Elastic SIEM, SIGMA rules, and Security Onion.
    • Designed training programmes that kept learner drop-off below 6% and contributed to a 20% reduction in cybersecurity incidents through structured threat-analysis training across the platform's learner base.
    • Analysed emerging threat-actor techniques and tooling, translating real adversary behaviour into teachable, hands-on labs for SOC and blue-team practitioners.
  2. Cyber Security Engineer

    Jun 2019 – Jan 2022

    Tabiri Analytics, Inc. · Nairobi, Kenya

    • Conducted end-to-end ISO 27001 / NIST 800-53 / CIS security audits for 10 enterprise clients in regulated industries, reaching compliance readiness within engagement timelines.
    • Led risk assessment and monitoring engagements: 40% improvement in client security posture, 20% gain in detection accuracy; authored the executive risk report that helped a client avert a ransomware attack and recover 20+ systems.
    • Deployed Elastic Stack SIEM across Windows/Linux/macOS for 5–80 endpoint clients, enabling continuous threat hunting and anomaly detection.
    • Managed third-party / vendor risk across multi-client portfolios and developed tailored security policies, cutting detection time to within 3 days.
  3. Web Application Security Engineer

    May 2018 – Dec 2018

    TeleTracking Technologies, Inc. · Kigali, Rwanda

    Securing a platform used live in clinical environments: patient flow, bed management, capacity operations.

    • Formalised vulnerability management with IBM AppScan: 40% reduction in pre-production defects in 3 months; hardened the telemedicine platform against the OWASP Top 10.
    • Reported compliance status to stakeholders, improving client compliance by 33%; authored 10 information security policies.

Capabilities

Skills & frameworks.

Frameworks & Standards

  • ISO 27001
  • NIST 800-53
  • NIST CSF
  • CIS Controls
  • GDPR
  • OWASP Top 10
  • MITRE ATT&CK

GRC & Governance

  • ISMS Design
  • Risk Register Management
  • Audit Readiness
  • Policy Development
  • Third-Party Risk
  • Board Reporting
  • Security Programme Management

Security Operations

  • SIEM (Elastic, Splunk, Wazuh)
  • Detection Engineering
  • SIGMA Rules
  • SOAR
  • Threat Hunting
  • Threat Intel (MISP, OpenCTI)
  • EDR
  • Incident Response
  • DFIR
  • Log Analysis

Tools & Platforms

  • IBM AppScan
  • Security Onion
  • TheHive
  • Suricata
  • Atomic Red Team
  • Volatility
  • Wazuh
  • ELK Stack

Credentials

Certifications & education.

CISSPISC202/2026 – 01/2029Active
GRC Analyst MasterclassTCM Security08/2023 – PresentActive
Certified Incident Responder (CIR)INE09/2024 – PresentActive
CAPMPMI05/2026 – PresentActive
Application Security AnalystIBM02/2016 – PresentActive
CySA+CompTIA05/2021 – 05/2024Expired
CIPTIAPP07/2019 – 07/2023Expired

M.Sc., Information Technology (Cybersecurity)

Carnegie Mellon University – Africa · Kigali, Rwanda · Jun 2019

B.Sc., Business Information Technology (Networking)

Strathmore University · Nairobi, Kenya · May 2016

Recognition

Awards & recognition.

  • International Visitors Leadership Program — Promoting CybersecurityU.S. Department of State · Oct 2021
  • MINDS Scholarship Programme for Leadership Development in AfricaMandela Institute for Development Studies · Aug 2017
  • Alumni Regional CoordinatorMINDS Africa · Oct 2025 – Present

Next step

Want the short version?

Download the CV, or see the work that backs all of this up.